zerofox logo
Advisories

Microsoft Patch Tuesday 09/13/2023 Notes

|by Alpha Team

banner image

Microsoft Patch Tuesday 09/13/2023 Notes

This advisory addresses and summarizes the vulnerabilities published by Microsoft this Patch Tuesday and highlights the most notable vulnerabilities that may impact our customers.

Recommendations

Keep up to date with the most recent vulnerabilities impacting you in our Vulnerabilities tab. Contact your account manager for more information. Be sure to apply patches promptly to mitigate these and other vulnerabilities.

Details

Highlights:

Microsoft's Patch Tuesday update for September 2023 contained 61 vulnerabilities, with:

  • 2 zero-day vulnerabilities
  • 5 vulnerabilities rated as Critical
  • 55 Vulnerabilities rated as High

(Microsoft defines a critical vulnerability as one whose exploitation could allow code execution without user interaction.)

Most notable vulnerabilities

This month’s patches include two actively exploited vulnerabilities, which require no user interaction, CVE-2023-36802 is a Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability while CVE-2023-36761 is a Microsoft Word Information Disclosure Vulnerability which includes the preview pane as an attack vector.

CVE-2023-36802

CVE-2023-36802 (CVSS score: 7.8) is a Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability. Microsoft stated that it is more likely to be exploited. Exploitation of this flaw would grant an attacker SYSTEM privileges.

The following products are affected:

  • Windows 10 Version 22H2 for 32-bit Systems
  • Windows 10 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2022 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2019
  • Windows 10 Version 1809 for ARM64-based Systems
  • Windows 10 Version 1809 for x64-based Systems
  • Windows 10 Version 1809 for 32-bit Systems

CVE-2023-36761

CVE-2023-36761 (CVSS score: 6.2) is a Microsoft Word Information Disclosure Vulnerability that has been actively exploited and was publicly disclosed before a patch was available. An attacker could use this vulnerability to disclose Windows NT LAN Manager hashes.

The following products are affected:

  • Microsoft Word 2013 Service Pack 1 (64-bit editions)
  • Microsoft Word 2013 Service Pack 1 (32-bit editions)
  • Microsoft Word 2013 RT Service Pack 1
  • Microsoft Word 2016 (64-bit edition)
  • Microsoft Word 2016 (32-bit edition)
  • Microsoft Office LTSC 2021 for 32-bit editions
  • Microsoft Office LTSC 2021 for 64-bit editions
  • Microsoft 365 Apps for Enterprise for 64-bit Systems
  • Microsoft 365 Apps for Enterprise for 32-bit Systems
  • Microsoft Office 2019 for 64-bit editions
  • Microsoft Office 2019 for 32-bit editions

CVE-2023-38148

CVE-2023-38148 (CVSS score: 8.8) is an Internet Connection Sharing (ICS) Remote Code Execution Vulnerability. An unauthorized attacker could exploit this vulnerability through a crafted network packet. It requires the victim to be connected to the same network segment as the attacker.

The following product is affected:

  • Windows 10 Version 22H2 for 32-bit Systems
  • Windows 10 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2022 (Server Core installation)
  • Windows Server 2022

CVE-2023-38149

CVE-2023-38149 (CVSS score: 7.5) is a Windows TCP/IP Denial of Service Vulnerability. It exists due to insufficient validation of input in Windows TCP/IP. A remote attacker can craft input to perform a denial of service (DoS) attack.

The following products are affected:

  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2016
  • Windows 10 Version 1607 for x64-based Systems
  • Windows 10 Version 1607 for 32-bit Systems
  • Windows 10 for x64-based Systems
  • Windows 10 for 32-bit Systems
  • Windows 10 Version 22H2 for 32-bit Systems
  • Windows 10 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2022 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2019
  • Windows 10 Version 1809 for ARM64-based Systems
  • Windows 10 Version 1809 for x64-based Systems
  • Windows 10 Version 1809 for 32-bit Systems

CVE-2023-38143

CVE-2023-38143 (CVSS score: 7.8) is a Windows Common Log File System Driver Elevation of Privilege Vulnerability. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.

The following products are affected:

  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
  • Windows Server 2008 for x64-based Systems Service Pack 2
  • Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
  • Windows Server 2008 for 32-bit Systems Service Pack 2
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2016
  • Windows 10 Version 1607 for x64-based Systems
  • Windows 10 Version 1607 for 32-bit Systems
  • Windows 10 for x64-based Systems
  • Windows 10 for 32-bit Systems
  • Windows 10 Version 22H2 for 32-bit Systems
  • Windows 10 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2022 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2019
  • Windows 10 Version 1809 for ARM64-based Systems
  • Windows 10 Version 1809 for x64-based Systems
  • Windows 10 Version 1809 for 32-bit Systems

Users are advised to apply the latest security patches specified in Microsoft's September 2023 Patch Tuesday update and follow the mitigations and workarounds to best protect themselves from the risks of these and other vulnerabilities.

Tags: technology,  all industries,  global, vulnerability/exploit